Highlights
-
CVE-2026-85046 Public
CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82
-
CVE-2026-28576-poc Public
Forked from mobilehackinglab/CVE-2026-28576-pocSQL injection vulnerability in Android 17 (AOSP)
Java UpdatedSep 7, 2026 -
-
CVE-2026-27876 Public
Grafana SQL Expressions Arbitrary File Write to RCE
Python UpdatedSep 6, 2026 -
CVE-2026-75604-poc Public
Forked from rafabd1/CVE-2026-75604-pocCVE-2026-75604 Next.js Windows RCE poc
-
CVE-2026-18963-Exploit Public
Forked from Snizi/CVE-2026-18963-ExploitExploit for KeyCloak CVE-2026-18963
-
anydesk-enum Public
AnyDesk pre-auth ID enumeration leaks public IP, internal network topology, and fingerprints via relay without target notification
-
chat-apps-osint Public
Forked from 0x6rss/chat-apps-osintPeer-metadata capture for chat-app calls (WhatsApp, Signal, Telegram ..etc). Authorized/consent use only. and more..
Python MIT License UpdatedAug 17, 2026 -
APTs-Adversary-Simulation Public
Forked from S3N4T0R-0X0/APTs-Adversary-SimulationThis repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stage…
C++ Other UpdatedAug 3, 2026 -
css-the-bomb-inside-your-inbox Public
Forked from PortSwigger/css-the-bomb-inside-your-inboxAll the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.
HTML UpdatedJul 30, 2026 -
canva-c2 Public
Forked from jeet-ganguly/canva-c2A security research project analyzing the potential misuse of Canva's public embed feature as a trusted cloud communication channel for Command-and-Control (C2).
C++ UpdatedJul 28, 2026 -
SeroC2 Public
Forked from SeroSkiid/SeroC2C2/RAT framework for authorized red team engagements and security research. HVNC, DXGI remote desktop 60fps, NativeAOT stub, 40+ features. Proprietary license — authorized use only.
-
OctoC2 Public
Forked from dstours/OctoC2GitHub-native command-and-control framework for authorized security research, with encrypted multi-channel transport and resilient failover.
TypeScript MIT License UpdatedJul 18, 2026 -
CL4R1T4S Public
Forked from elder-plinius/CL4R1T4SLEAKED SYSTEM PROMPTS FOR CHATGPT, CLAUDE, GEMINI, GROK, PERPLEXITY, CURSOR, LOVABLE, REPLIT, AND MORE! - AI SYSTEMS TRANSPARENCY FOR ALL! 👐
GNU Affero General Public License v3.0 UpdatedJun 9, 2026 -
BEAR-c2 Public
Forked from S3N4T0R-0X0/BEAR-C2Bear C2 is a compilation of C2 scripts, payloads, and stagers used in simulated attacks by Russian APT groups, Bear features a variety of encryption methods, including AES, XOR, DES, TLS, RC4, RSA …
C++ UpdatedJun 9, 2026 -
Notepad-8.9.6-PoC Public
Proof-of-concept scripts for three vulnerabilities in Notepad++ <= 8.9.6, patched in v8.9.6.1 (2026-05-26) CVE-2026-48770 / CVE-2026-48778 / CVE-2026-48800
-
-
CVE-2026-42897 Public
CVE-2026-42897 - Exchange Health Checker blind spot: outbound IIS URL Rewrite rules silently ignored, making EOMT mitigations invisible in diagnostic reports.
-
-
cortex Public
Forked from intelseclab/cortexA modern system configuration tool for Linux, built with GTK4 and Python (libadwaita). Cortex brings together system tweaks, privacy controls, and Tor/network management in one clean interface.
Python UpdatedApr 21, 2026 -
-
-
-
GeoIntel Public
GeoIntel using Google's Gemini API to uncover the location where photos were taken through AI-powered geo-location analysis.
-
-
-
-
unmapjs Public
Recover source files from sourcemaps of any React, Next.js, Vite, or Webpack-based web application
-
pentagi Public
Forked from vxcontrol/pentagi✨ Fully autonomous AI Agents system capable of performing complex penetration testing tasks
Go MIT License UpdatedFeb 16, 2026 -